Fake Bank/PayPal/iTunes emails lead to malware
FYI...
Malicious ‘Security Update for Banking Accounts’ emails lead to BlackHole Exploit Kit
-
http://blog.webroot.com/2012/12/07/...counts-emails-lead-to-black-hole-exploit-kit/
Dec 7, 2012 - "Cybercriminals have recently launched yet another massive spam campaign attempting to trick e-banking users into thinking that their ability to process ACH transactions has been temporarily disabled. Upon clicking on the link found in the malicious email, users are exposed to the client-side exploits served by the
Black Hole Exploit Kit...
Sample screenshot of the spamvertised email:
>
https://webrootblog.files.wordpress...pdate_banking_email_spam_exploits_malware.png
Sample spamvertised compromised URLs:
hxxp ://promic .pl/page4.htm
hxxp ://promic .pl/rating.htm
Sample client-side exploits serving URLs:
hxxp ://bamanaco .ru:8080/forum/links/column.php
hxxp ://lentuiax .ru:8080/forum/links/column.php
Malicious domains reconnaissance:
bamanaco.ru –
82.165.193.26 (AS8560); 203.80.16.81 (AS24514); 216.24.196.66 (AS40676)
Name servers:
ns1.bamanaco .ru -
62.76.178.233
ns2.bamanaco .ru –
41.168.5.140
ns3.bamanaco .ru –
132.248.49.112
ns4.bamanaco .ru –
209.51.221.247
lentuiax .ru –
203.80.16.81 (AS24514)
Name servers:
ns1.lentuiax .ru –
62.76.178.233
ns2.lentuiax .ru –
41.168.5.140
ns3.lentuiax .ru –
132.248.49.112
ns4.lentuiax .ru –
209.51.221.247
Sample detection rate for the redirection script: MD5: 35e6ddb6ce4229d36c43d9d3ccd182f3 * ... Trojan-Downloader.JS.Iframe.dby.
Although we couldn’t reproduce the malicious exploitation taking place through bamanaco .ru and lentuiax .ru, we found out that, during the time of the attack, similar client-side exploit serving URls were also responding to the same IPs, leading us to the actual malicious payload found on two of these domains..."
(More detail available at the webroot URL above.)
*
https://www.virustotal.com/file/ff5...e817b9c2d293c174c3e7aab1/analysis/1353822844/
File name: August.html
Detection ratio:
21/44
Analysis date: 2012-11-25
___
Fake PayPal Emails: Windows 8 and Vintage Photo Collections
-
http://www.gfi.com/blog/fake-paypal-emails-windows-8-and-vintage-photo-collections/
Dec 7, 2012 - "If you want to panic over a mysterious transaction on Ebay to the tune of $564.48 for a “Microsoft Windows 8 Pro Anytime Upgrade”, then this is probably the email you’ve been waiting for.
It reads:
You have made an Ebay.com purchase.
Hello [removed],
You sent a payment of $564.48 USD to [removed].
Microsoft Windows 8 Pro Anytime Upgrade
Item# 16 $564.48 USD
>
http://www.gfi.com/blog/wp-content/uploads/2012/12/ebaywin8.png
Clicking the link in the
fake PayPal email will take end-users to the usual round of
Cridex / Blackhole URLs. On a similar note, there’s an additional email floating around that claims you purchased 84 copies of “Vintage photo collection sexy college girls 1990s or 2000s”.
>
http://www.gfi.com/blog/wp-content/uploads/2012/12/ebaywin82.png
Last time we saw this one was back in June* where the tally was -23- ..."
*
http://blog.dynamoo.com/2012/06/paypal-spam-itscholarshipznet.html
___
iTunes "Christmas gift card" SPAM / api.myobfuscate .com / nikolamireasa .com
-
http://blog.dynamoo.com/2012/12/itunes-christmas-gift-card.html
6 Dec 2012 - "Here's a
malware-laden spam with a twist:
From: iTunes [shipping @new. itunes .com]
To: purchasing [purchasing @ [redacted]]
Date: 6 December 2012 20:59
Subject: Christmas gift card
Order Number: M1V7577311
Receipt Date: 06/12/2012
Shipping To: purchasing @[redacted]
Order Total: $500.00
Billed To: Hilary Shandonay, Credit card
Item Number Description Unit Price
1 Christmas gift card (View\Download ) $500.00
Subtotal: $500.00
Tax: $0.00
Order Total: $500.00
Please retain for your records.
Please See Below For Terms And Conditions Pertaining To This Order.
Apple Inc.
You can find the iTunes Store Terms of Sale and Sales Policies by launching your iTunes application and clicking on Terms of Sale or Sales Policies
FBI ANTI-PIRACY WARNING
UNAUTHORIZED COPYING IS PUNISHABLE UNDER FEDERAL LAW.
Answers to frequently asked questions regarding the iTunes Store can be found at http ://www.apple .com/support/itunes/store/
Apple ID Summary ??????????¬?‚?? Detailed invoice
Apple respects your privacy.
Copyright ??????‚?© 2011 Apple Inc. All rights reserved
In this case the link goes through a free web hosting site at [donotclick]longa-neara.ucoz .org which contains some
heavily obfuscated javascript that eventually leads to a malicious landing page on [donotclick]nikolamireasa .com/less/demands-probably.php hosted on
188.93.210.133 (logol .ru, Russia). That IP hosts the following
toxic domains that you should block:
nikolamireasa .com
portgazza. cu .cc
hopercac. cu .cc
hopercas. cu .cc
ukumuxur. qhigh .com
ymuvyjih.25u .com
... you might just want to cut your losses and
block 188.93.210.0/23 too. Anyway, the curious thing is that the malicious javascript uses an intermediary obfuscation site called api.myobfuscate .com... if the bad guys have a use for it then you can bet they are probably about to abuse it in a big way. Both api.myobfuscate .com and www .myobfuscate .com are hosted on the same IP at
188.64.170.17 (also in Russia) which is part of a tiny netblock of
188.64.170.16/31 which you
may as well block too. The
188.64.170.17 IP also contains the following domains which might also be abused in the same way:
htmlobfuscator .com
api.htmlobfuscator .com
htmlobfuscator .info
javascript-obfuscator .info
javascriptcompressor .info
javascriptcrambler .com
javascriptobfuscate .com
javascriptobfuscator .info
myobfuscate .com
api.myobfuscate .com
obfuscatorjavascript .com
api.obfuscatorjavascript .com
js.robotext .com
js.robotext .info
js.robottext .ru
In my opinion, obfuscating javascript is a really bad thing and there is no legitimate reason to use it. Blocking access to free-to-use obfuscation tools like this may run the risk of breaking some legitimate sites. But only if they have been coded by idiots."
-
http://www.avgthreatlabs.com/webthreats/
... last updated on Dec 08, 2012 GMT.
Viruses & Threats on the Rise
1) Cool Exploit Kit - 19.24% of all detections...
2) Blackhole Exploit Kit - 19.16% of all detections...
3)
JavaScript Obfuscation - 12.70% of all detections...
___
AICPA SPAM / ibertomoralles .org
-
http://blog.dynamoo.com/2012/12/aicpa-spam-ibertomorallesorg.html
7 Dec 2012 - "I haven't seen
fake AICPA spam like this for a while, it
leads to malware on ibertomoralles .org:
From: AICPA [noreply@aicpa.org]
Date: 7 December 2012 16:55
Subject: Your accountant license can be cancelled.
You're receiving this information as a Certified Public Accountant and a member of AICPA.
Having any problems reading this email? See it in your favorite browser.
AICPA logo
Revocation of CPA license due to income tax fraud accusations
Dear AICPA participant,
We have been informed of your potential involvement in tax return swindle on behalf of one of your employers. In obedience to AICPA Bylaw Article 700 your Certified Public Accountant position can be discontinued in case of the aiding of filing of a phony or fraudulent income tax return for your client or employer.
Please be notified below and provide explanation of this issue to it within 14 work days. The rejection to provide elucidation within this time-frame would finish in decline of your Accountant status.
Delation.pdf
The American Institute of Certified Public Accountants.
Email: service @aicpa .org
Tel. 888.777.7077
Fax. 800.362.5066
===================
Date: Fri, 7 Dec 2012 18:31:58 +0100
From: "AICPA" [do-not-reply @aicpa .org]
Subject: Tax return assistance contrivance.
You're receiving this note as a Certified Public Accountant and a part of AICPA.
Having any problems reading this email? See it in your favorite browser.
Cancellation of Public Account Status due to tax return indictment
Respected accountant officer,
We have received a note of your presumable interest in income tax fraud for one of your clients. In concordance with AICPA Bylaw Article 600 your Certified Public Accountant status can be discontinued in case of the event of submitting of a fake or fraudulent income tax return on the member's or a client's behalf.
Please familiarize yourself with the complaint below and provide your feedback to it within 14 work days. The rejection to respond within this time-frame will result in end off of your CPA license.
Delation.doc
The American Institute of Certified Public Accountants.
Email: service@aicpa.org
Tel. 888.777.7077
Fax. 800.362.5066
The malicious payload is at [donotclick]ibertomoralles.org/detects/five-wise_leads_ditto.php hosted on the same Chinese IP address of
59.57.247.185 as used in this spam yesterday*."
*
http://blog.dynamoo.com/2012/12/ebay-paypal-spam-ibertomorallescom.html
___
BBB SPAM / ibertomoralles .org
-
http://blog.dynamoo.com/2012/12/bbb-spam-ibertomorallesorg.html
"This bizarrely worded
fake BBB spam leads to malware on ibertomoralles .org:
Date: Fri, 7 Dec 2012 18:43:08 +0100
From: "Better Business Bureau" [complaint @bbb .org]
Subject: BBB Complaint No.65183683
Sorry, your e-mail does not support HTML format. Your messages can be viewed in your browser
Better Business Bureau �
Start With Trust �
Fri, 7 Dec 2012
RE: Complaint N. 65183683
Hello
The Better Business Bureau has been booked the above said complaint from one of your purchasers in regard to their business relations with you. The detailed description of the consumer's disturbance are available visiting a link below. Please give attention to this point and let us know about your mind as soon as possible.
We amiably ask you to overview the GRIEVANCE REPORT to reply on this claim letter.
We are looking forward to your prompt reaction.
Faithfully yours
Natalie Richardson
Dispute Councilor
Better Business Bureau
3073 Wilson Blvd, Suite 600 Arlington, VA 28201
Phone: 1 (703) 276.0100 Fax: 1 (703) 525.8277
This message was sent to [redacted]. Don't want to receive these emails anymore? You can unsubscribe
====================
Date: Fri, 7 Dec 2012 19:42:23 +0200
From: "Better Business Bureau" [noreply@bbb.org]
Subject: BBB Appeal No.05P610Q78
Sorry, your e-mail does not support HTML format. Your messages can be viewed in your browser
Better Business Bureau �
Start With Trust �
Fri, 7 Dec 2012
RE: Case # 05P610Q78
Hello
The Better Business Bureau has been filed the above said reclamation from one of your customers in respect of their dealings with you. The details of the consumer's disturbance are available at the link below. Please pay attention to this issue and notify us about your sight as soon as possible.
We politely ask you to visit the PLAINT REPORT to meet on this claim.
We are looking forward to your prompt reaction.
Yours respectfully
Dylan Peterson
Dispute Councilor
Better Business Bureau
3003 Wilson Blvd, Suite 600 Arlington, VA 25301
Phone: 1 (703) 276.0100 Fax: 1 (703) 525.8277
This message was delivered to [redacted] Don't want to receive these emails anymore? You can unsubscribe
====================
From: Better Business Bureau [mailto:information@bbb.org]
Sent: Fri 07/12/2012 17:01
Subject: Better Business Beareau Pretension No.S8598593
Sorry, your e-mail does not support HTML format. Your messages can be viewed in your browser
Better Business Bureau ©
Start With Trust
Fri, 7 Dec 2012
RE: Complaint N. S8598593
Valued client
The Better Business Bureau has been entered the above mentioned grievance from one of your clientes with reference to their dealings with you. The details of the consumer's worry are available at the link below. Please give attention to this problem and let us know about your opinion as soon as possible.
We pleasantly ask you to click and review the CLAIM LETTER REPORT to respond on this grievance.
We awaits to your prompt response.
WBR
Aiden Thompson
Dispute Advisor
Better Business Bureau
3003 Wilson Blvd, Suite 600 Arlington, VA 26701
Phone: 1 (703) 276.0100 Fax: 1 (703) 525.8277
This letter was delivered to [redacted]. Don't want to receive these emails anymore? You can unsubscribe
The payload and IP addresses are exactly the same as the ones found in this spam run*."
*
http://blog.dynamoo.com/2012/12/aicpa-spam-ibertomorallesorg.html
___
Sendspace "You have been sent a file" SPAM / pelamutrika .ru
-
http://blog.dynamoo.com/2012/12/sendspave-you-have-been-sent-file-spam.html
7 Dec 2012 - "This
fake Sendspace spam leads to malware on pelamutrika .ru:
Date: Fri, 7 Dec 2012 10:53:57 +0200
From: Badoo [noreply @badoo .com]
Subject: You have been sent a file (Filename: [victimname]-64.pdf)
Sendspace File Delivery Notification:
You've got a file called [victimname]-792244.pdf, (337.19 KB) waiting to be downloaded at sendspace.(It was sent by CHASSIDY PROCTOR).
You can use the following link to retrieve your file:
Download Link
The file may be available for a limited time only.
Thank you,
sendspace - The best free file sharing service.
----------------------------------------------------------------------
Please do not reply to this email. This auto-mailbox is not monitored and you will not receive a response.
The malicious payload is at [donotclick]pelamutrika .ru:8080/forum/links/column.php hosted on the following familiar IP addresses which you should definitely try to block:
202.180.221.186 (GNet, Mongolia)
208.87.243.131 (Psychz Networks, US)"
___
Searching for “Windows Android Drivers” Leads to Malware and Bogus Google Play Markets
-
http://www.gfi.com/blog/searching-f...ads-to-malware-and-bogus-google-play-markets/
7 Dec 2012 - "If you’re on the lookout for Android USB drivers for your Windows OS,
be very careful. Such strings like “Windows Android Drivers” or combinations of these may bring up results that you would rather stay away from. Our researchers in the AV Labs have found this peculiar search result on Yahoo!... Visiting the Russian URL, bestdrivers(dash)11(dot)ru, automatically downloads a file called
install.exe... Running the .exe file, which is a Trojan that we detect as Trojan.Win32.Generic!BT, allows it to modify the start page of the user’s IE browser to 94(dot)249(dot)188(dot)143/stat/tuk/187, a sign-up page for a Russian “escort” site. It does this so users are directed to the page by default whenever they open their IE browser..." (
-aka- Hijacked...)
(More detail and screenshots at the gfi URL above.)
___
Christmas themed SCAMS on Facebook ...
-
http://community.websense.com/blogs/securitylabs/archive/2012/12/06/merry-xmas-on-facebook.aspx
06 Dec 2012 - "... We spotted more than 3,000 unique URLs used for this scam on Facebook. The high variation is used by cyber criminals to assure persistence and redundancy in case some URLs or domains get blacklisted.
>
http://community.websense.com/cfs-f...iles/securitylabs/1007.Facebook_5F00_xmas.jpg
... Here are some of the offending IP addresses found to be part of the scam infrastructure hosting the scam web sites:
208.73.210.147
213.152.170.193
184.107.164.158
216.172.174.53
199.188.206.214
198.187.30.161
198.154.102.28
68.168.21.68
198.154.102.29
174.132.156.176
198.154.102.27
88.191.118.153
208.91.199.252
We believe that this attack is now under control and is being successfully mitigated by Facebook. We're seeing a gradual decline in incidences, but it's safe to say that while it's declining it's still going strong..."
